CVE-2026-75098 WordPress Product Designer App 插件目录遍历漏洞
影响未授权攻击者可读取服务器上任意文件内容
WordPress 的 Product Designer App 插件在所有 1.1.3 及之前版本中存在目录遍历漏洞,攻击者可通过 svg 参数读取服务器任意文件。该插件的访问控制仅依赖 nonce 和 token,而这两者会作为 JavaScript 全局变量在渲染 [pdapp-studio-page] 短代码的任意页面上公开输出,匿名访客即可获取,因此无需认证即可利用。
影响范围
Product Designer App 插件所有版本至 1.1.3(含)。
漏洞详情
漏洞类型为目录遍历(路径穿越),成因是插件对 svg 参数未做充分的路径过滤与规范化,导致可跳出预期目录访问任意文件。利用方式为匿名请求携带构造的 svg 参数,配合从页面 JavaScript 全局变量中获取的 nonce 与 token 绕过校验,从而读取服务器上的敏感文件。
利用条件与风险
利用前提是目标站点启用了该插件并渲染了相关短代码页面,攻击者无需任何账号即可获取 nonce/token 并发起请求;实战中可导致配置文件、密钥等敏感信息泄露,风险较高。
修复建议
官方已发布修复版本,建议升级至 1.1.3 之后的版本;若暂无可用更新,可临时禁用该插件或限制对相关接口的访问。
The Product Designer App plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.3 via the ‘svg’ parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The endpoint’s only authentication gate relies on a nonce and token that are both publicly emitted as JavaScript globals on any page rendering the [pdapp-studio-page] shortcode, making them freely obtainable by anonymous visitors.